← Zuruck zu CVEs
CVE-2026-27138
MEDIUM5.9
Beschreibung
Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains, or those that use TLS.
CVE Details
CVSS v3.1 Bewertung5.9
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
AngriffsvektorNETWORK
KomplexitatHIGH
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/6/2026
Zuletzt geandert3/10/2026
Quellenvd
Honeypot-Sichtungen0
Referenzen
https://go.dev/cl/752183(security@golang.org)
https://go.dev/issue/77953(security@golang.org)
https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk(security@golang.org)
https://pkg.go.dev/vuln/GO-2026-4600(security@golang.org)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.